← Blog

Data Breaches List of Salesforce

Share on X

Looking for a complete Salesforce data breaches list? This page answers common searches like "Salesforce hacked," "Salesforce breach history," and "list of Salesforce data breaches" with a verified timeline, record counts, root causes, and step-by-step guidance if you may have been affected.

Salesforce data breach history: As the CRM backbone of the Fortune 500, Salesforce incidents ripple through Marketing Cloud APIs and the 2026 ShinyHunters vishing wave. BreachHistory indexes 2 verified or attested incidents tied to Salesforce, spanning 2018–2026. This page is a complete, searchable timeline—not a single event—linking every catalog row with context on scale, root cause, and what users should do when a new Salesforce notice drops.

Why Salesforce stays on breach trackers

Global tech brands combine massive user bases, high-value intellectual property, and complex supply chains. Attackers target Salesforce for credentials, source code, CRM exports, and employee directories. When you read headlines about "Salesforce hacked," the incident may be a consumer PII leak, a developer artifact exposure, or a third-party SaaS tenant breach—each with different remediation steps.

Data breaches list — Salesforce

Below are the major incidents in our catalog, newest first. Record counts use company, regulator, or Have I Been Pwned attestation where available; actor-only marketing shows as "Unverified / not disclosed."

Biggest and most consequential incidents

2026 Salesforce ecosystem — ShinyHunters vishing wave against CRM tenants (platform context)

Throughout 2026, ShinyHunters and copycat actors exploited voice-phishing against employees to steal Microsoft Entra session tokens and bulk-export Salesforce CRM data from many tenants. Salesforce published security guidance and platform detections; individual victim counts (Charter 4.9M, Cisco ~3M marketing, McGraw Hill 13.5M emails, etc.) belong to each customer organization. BreachHistory indexes this contextual row under Salesforce with recordsAffected 0 to document the platform-wide campaign without double-co… Full incident record →

2018 — Cloud behemoth Salesforce.com is warning customers…

Cloud behemoth Salesforce.com is warning customers about an API error that may have leaked data for some users of its Marketing Cloud offering. The issue was in play between June 4 to July 18, Full incident record →

By the numbers (catalog snapshot)

  • 2 incidents indexed under Salesforce on BreachHistory
  • Unverified / not disclosed combined attested records across rows with disclosed numerators (many incidents overlap or count emails—not unique people)
  • 2026 — year of the largest attested row in our catalog

Patterns in Salesforce's breach history

  • Credential and session theft — Phishing, stuffing, and OAuth token abuse recur across tech platforms.
  • Cloud misconfiguration — S3 buckets, misconfigured APIs, and file shares expose data without a traditional "hack."
  • Extortion without precise counts — Ransomware and leak-site actors often publish before victims confirm scope.
  • Supply-chain spillover — npm, SDK, and CRM tenant breaches affect Salesforce customers even when corporate HQ databases stay intact.

What to do if you used Salesforce

  1. Enable multi-factor authentication on every Salesforce account and linked SSO identity.
  2. Check Have I Been Pwned when new Salesforce headlines appear.
  3. Rotate passwords that were reused on email, banking, or work SSO.
  4. Watch for phishing that cites real breach details (order numbers, usernames) to appear legitimate.
  5. Follow official Salesforce security communications—not SMS links from unknown numbers.

Related searches

FAQ

How many data breaches has Salesforce had?

BreachHistory indexes 2 verified or attested Salesforce data breaches spanning 2018–2026. Counts vary when researchers merge scraping, misconfiguration, and ransomware as separate events.

What is the biggest Salesforce data breach?

Several Salesforce incidents lack a disclosed record count. See the timeline for source-code thefts, extortion claims, and confirmed consumer notices.

Has Salesforce been hacked?

Yes — Salesforce appears on breach trackers with 2 indexed incidents including major security incidents. This page links every catalog row with primary sources and what users should do if affected.

Does Salesforce send data breach notifications?

Regulated markets require consumer notices for many PII events. Not every source-code or scraping story triggers email alerts—read each incident row for notification status.

Explore every Salesforce incident on BreachHistory

Browse the full catalog: Salesforce breach records

Compiled from BreachHistory data/breaches.json and primary sources linked on each incident page. Updated 2026-06-15.